Macintouch is showing an AS script:
http://www.macintouch.com/#notesandtips
I've never been comfortable with AS, so I'm thinking about installing
it to see how it works, then re-writing it in perl, and maybe even
further trap all attempts to climb the directory tree in the uri.
(With any luck, Apple will have at least a patch to trap URIs that
attempt to access directories above /Library before I'm finished. It
occurs to me I've seen this exploit used in the past. I don't think the
attacker accomplished anything other than leaving me with an unexpected
disk image on the desktop and lifesaver in the menu bar. I re-install
my system periodically, because I know Apple's in the expansion phase
with this OS, and I expect these kinds of holes to show up.)
Chris Nandor - 26 May 2004 14:49 GMT
> Macintouch is showing an AS script:
>
[quoted text clipped - 3 lines]
> it to see how it works, then re-writing it in perl, and maybe even
> further trap all attempts to climb the directory tree in the uri.
You can use Mac::InternetConfig to "disable" the protocol handlers. But
RCDefaultApp is a better solution for this.

Signature
Chris Nandor pudge@pobox.com http://pudge.net/
Open Source Development Network pudge@osdn.com http://osdn.com/